交换机 网线 机房
组网步骤:准备工作:在拓扑图上规划好IP地址和VLAN。配置RTA(对外路由器)根据ISP提供的IP网段配置外网接口,然后用PING命令测试外网网关是否通配置内网NAT相关ACL(访问控制列表)在外网接口中用NAT
参考配置:假定ISP分给以下数据其中一个网段:DNS:172.18.0.253 220.187.24.2A:61.153.208.64-67网关:61.153.208.65B:61.153.208.68-71网关:61.153.208.69C:61.153.208.72-75网关:61.153.208.73D:61.153.208.76-79网关:61.153.208.75比如IP段:61.153.208.64-67网关:61.153.208.65DNS:220.187.24.2规划内网IP段如下:公共网段:172.16.0.0/24 其中RTA为172.16.0.1/24 S1为172.16.0.2 S2:172.16.0.3/24S3:172.16.0.4/24Web服务器IP:172.16.0.5/24 域名为:http://www.test.com部门A网段:192.168.0.0/24网关:192.168.0.1/24部门B网段:192.168.1.0/24 网关:192.168.1.1/24配置RTA:sysname Wang_Guanacl number 2000rule permit source 192.168.0.0 0.0.0.255rule permit source 192.168.1.0 0.0.0.255acl number 3000rule deny ip source 192.168.0.0 0.0.0.255 destnation 192.168.1.0 0.0.0.255rule deny ip source 192.168.1.0 0.0.0.255 destnation 192.168.0.0 0.0.0.255interface e0/0ip address 61.153.208.66 255.255.255.252nat outbound 2000nat server protocol tcp global 61.153.208.66 www inside 172.16.0.5 wwwinterface e0/1ip address 172.16.0.1 24firewall packet-filter 3000 inboundip route-static 0.0.0.0 0 61.153.208.65ip route-static 192.168.0.0 24 172.16.0.2ip route-static 192.168.1.0 24 172.16.0.2dns server 220.187.24.2dns resolvenat dns-map www.test.com 61.153.208.66 80firewall enable用PING测试对外网网关应该都能通,测试通过用SAVE进行保存。配置S1 (用1-8号口用于部门A主机相连,不够接S2中1-8号口,9-16号接部门B主机,不够接S3中9-15号口,23、24号口分别接S2和S3的16号口,17-22号口接路由器和服务器)sysname He_Xinvlan 20port e1/0/1 to e1/0/8vlan 30port e1/0/9 to e1/0/16interface vlan 1ip address 172.16.0.2 255.255.255.0interface vlan 20ip address 192.168.0.1 255.255.255.0interface vlan 30ip address 192.168.1.1 255.255.255.0interface e1/0/23port link-type trunkport trunk permit vlan 1 20 30interface e1/0/24port link-type trunkport trunk permit vlan 1 20 30acl number 3000rule deny ip source 192.168.0.0 0.0.0.255 destnation 192.168.1.0 0.0.0.255acl number 3001rule deny ip source 192.168.1.0 0.0.0.255 destnation 192.168.0.0 0.0.0.255interface e1/0/1packet-filter 3000 inboundinterface e1/0/2packet-filter 3000 inboundinterface e1/0/3packet-filter 3000 inboundinterface e1/0/4packet-filter 3000 inboundinterface e1/0/5packet-filter 3000 inboundinterface e1/0/6packet-filter 3000 inboundinterface e1/0/7packet-filter 3000 inboundinterface e1/0/8packet-filter 3001 inboundinterface e1/0/9packet-filter 3001 inboundinterface e1/0/10packet-filter 3001 inboundinterface e1/0/11packet-filter 3001 inboundinterface e1/0/12packet-filter 3001 inboundinterface e1/0/13packet-filter 3001 inboundinterface e1/0/14packet-filter 3001 inboundinterface e1/0/15packet-filter 3001 inboundinterface e1/0/16ip route-static 0.0.0.0 0 172.16.0.1配置S2、S3(两台除管理用IP地址不一样其余配置相同)sysname S2vlan 20port e0/1 to e0/8vlan 30port e0/9 to e0/15interface vlan 1ip address 172.16.0.3 255.255.255.0interface e0/16port link-type trunkport trunk permit vlan 1 20 30***************************************************sysname S3vlan 20port e0/1 to e0/8vlan 30port e0/9 to e0/15interface vlan 1ip address 172.16.0.4 255.255.255.0interface e0/16port link-type trunkport trunk permit vlan 1 20 30